Apache OFBiz 18.12.10, vulnerable to CVE-2023-51467: a request with `requirePasswordChange=Y` passes the authentication check, which reaches the webtools ProgramExport screen and runs Groovy code on the server.
Pas commencéDockercommit 04820cax86_64 · aarch64Secret
Exploit CVE-2023-51467 to bypass the login, run code on the OFBiz server and get a shell.
Le brief de ce lab se trouve dans son dépôt.